Unrated severityNVD Advisory· Published Sep 2, 2026
CVE-2026-84668
CVE-2026-84668
Description
Jenkins SAML Plugin 4.618.v441a_27fa_46d2 and earlier allows overwriting the SAML identity provider metadata file through Stapler data binding, allowing attackers to replace it with attacker-controlled content and authenticate as any user.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=4.618.v441a_27fa_46d2
Patches
Vulnerability mechanics
References
1News mentions
1- Jenkins Security Advisory 2026-09-02Jenkins Security Advisories · Sep 2, 2026